Sub-processor List
Last updated: August 28, 2026
1. Overview & Commitment
This page discloses all third-party data processors involved with GateLLM, in two categories: GateLLM platform sub-processors (engaged by Fluxon LLC to operate account, license, and support services) and downstream model providers (selected and configured by you via BYOK).
Our commitment: no shadow AI, no hidden sub-processors. All platform sub-processors are fully disclosed here; the data-use practices of each downstream model provider are annotated so that you know whether a provider will train on or retain your data before you onboard it. This list is updated in real time as changes occur, and you can subscribe to email notifications.
Scope: this list covers only the sub-processors involved in the website, license issuance service, and support services operated by the Processor (Fluxon LLC). GateLLM is a self-hosted software product — when you run it deployed on your own infrastructure, that instance does not pass through any of the Processor's sub-processors; the downstream model providers you configure on your self-hosted instance engage directly with you (see Section 3) and are not sub-processors of the Processor.
2. GateLLM Platform Sub-processors
The following sub-processors are engaged by Fluxon LLC to operate account, license, payment, and support services. They do not come into contact with the prompts or completions processed by GateLLM at runtime (see DPA Section 8.1).
- Supabase Inc. — Database storage & authentication | Purpose: accounts, license data | Region: US (US-East) | Personal data processed: contact info, account credentials, license status | DPA: signed | Adequacy: via SCCs
- Stripe Inc. — Payment processing | Purpose: billing & collection | Region: US (routed by card network) | Personal data processed: billing info (Stripe-compliant directly, PCI-DSS Level 1) | DPA: signed | Adequacy: via SCCs
- Resend Inc. — Email delivery | Purpose: notifications & support tickets | Region: US (US-East) | Personal data processed: email address, email content | DPA: signed | Adequacy: via SCCs
- Functional Software, Inc. (Sentry) — Error monitoring | Purpose: diagnosing frontend & backend errors | Region: US / EU (per project config) | Personal data processed: error stack traces, browser type, IP address | DPA: signed | Does not process prompt content | Adequacy: via SCCs
- Google LLC — Analytics (cookies) | Purpose: site traffic statistics | Region: US (under EU-US DPF) | Personal data processed: online identifiers (client ID), device/browser data | DPA: signed (Google Ads Data Processing Terms) | Adequacy: EU-US DPF (SCCs fallback) | Retention: 2 months
All platform sub-processors are bound by written agreements providing the same level of data protection as this DPA. Frontend Sentry is consent-gated and loaded only after the user accepts analytics.
3. Downstream Model Providers (BYOK, configured by you)
GateLLM connects to 100+ downstream model providers via BYOK. The data-use matrix below is compiled from each provider's publicly stated policies to help you assess data risk before onboarding.
Important: you engage providers directly using your own API keys. Keys live only in the gateway process memory within your infrastructure — never persisted, never transmitted. Whether a provider is used, and whether prompts containing personal data are sent to it, is entirely your decision, fully opt-in. GateLLM ships with no provider connections pre-configured.
3.1 Downstream Model Provider Data-Use Matrix
Matrix field definitions: "Training use" indicates whether the provider uses your API request data to train its models; "Data retention" indicates the retention policy for non-training purposes; "Primary region" indicates the provider's primary data-processing region (relevant for cross-border assessment); "Policy source" links to the provider's public policy. Providers marked "not used for training by default" typically offer opt-out or enterprise-tier exemptions; you should independently verify the latest policy.
- Anthropic — Training: not used by default (enterprise/API traffic exempt) | Retention: 30 days (deleted after anomaly detection) | Region: US | Policy: anthropic.com/legal/privacy
- OpenAI — Training: not used by default (API traffic, unless explicitly opted in) | Retention: deleted after 30 days (except abuse detection) | Region: US | Policy: openai.com/policies/privacy-policy
- Google (Gemini API) — Training: not used by default (Paid API, can disable) | Retention: per cloud region | Region: global (GCP regions) | Policy: cloud.google.com/terms/data-processing-addendum
- Zhipu AI — Training: enterprise tier exempt | Retention: per contract | Region: China | Policy: zhipuai.cn/privacy
- Alibaba Cloud (Tongyi/DashScope) — Training: enterprise tier exempt | Retention: per log policy | Region: China | Policy: help.aliyun.com/document_detail/468551.html
- DeepSeek — Training: see latest official policy | Retention: see official site | Region: China | Policy: deepseek.com/privacy
- Mistral AI — Training: API traffic not used by default | Retention: per contract | Region: EU (France) | Policy: mistral.ai/privacy-policy
- Cohere — Training: enterprise tier exempt | Retention: per contract | Region: Canada/EU | Policy: cohere.com/privacy
- Other providers — data-use practices for 100+ providers: verify the latest policy on the provider's website before onboarding, or contact security@gatellm.io for assistance
This matrix is compiled from providers' publicly stated policies and may change as those policies are updated. We recommend that you independently verify a provider's latest data policy before onboarding — particularly before sending prompts containing personal data — and execute any necessary agreements (such as the provider's own DPA).
4. Change Notification & Subscription
We commit to notifying you in advance of any addition, replacement, or removal of GateLLM platform sub-processors and providing an opportunity to object (see DPA Section 8.3 for details):
- Notification timeline: at least 30 days before a new sub-processor goes live (at least 90 days for sensitive data transfers)
- Notification channels: the change log on this page + the email registered in your account
- Objection window: raise a reasonable objection within 30 days of the notice
- Email subscription: email security@gatellm.io to subscribe to sub-processor change notifications so none are missed
Changes to the downstream model provider list are decided by you (adding/removing keys) and are not subject to this notification process; however, we continuously maintain and update the data-use matrix above.
5. Change Log
The history of changes to this list is recorded below:
- 2026-08-28: Replaced the analytics sub-processor Plausible Insights Ltd. with Google LLC (purpose: site analytics; region: US under EU-US DPF; retention 2 months; Google Data Processing Terms accepted)
- 2026-08-12: added this page, fully disclosing platform sub-processors and the downstream model provider data-use matrix
- 2026-08-12: DPA updated in tandem, clarifying the legal-status distinction between platform sub-processors and downstream model providers (Section 8.2)
6. Contact
For sub-processor questions or to subscribe to change notifications, contact: security@gatellm.io. For data protection inquiries: privacy@gatellm.io.
GateLLM is a product of Fluxon LLC, a Delaware limited liability company.